Your personal data has already been stolen. How not to give attackers to use them?
The last week, which at once contains two allegedly multimillion -dollar leaks of sensitive data that occurred according to completely different scenarios, showed how outstanding the usual ideas about the protection of personal data are. You cannot be sure that your data has not leaked from government agencies, the country's largest bank or mobile application that you use every day. Worse: most likely, your data has already been stolen. Now your main goal is to prevent attackers to use them.
This article was written for the weekly final mailing of The Bell . You can subscribe to it here .
What's happened
Tax base. The first leak became known on Tuesday, but it happened at least a year ago. The unknown owner left an open access in the Amazon cloud with data of 20 million Russians - FULL NAME, TIN and all tax payments. The stored information covered the period from 2009 to 2016 and was available at least from May 2018, when the search engines were first indexed. In the Federal Tax Service, the leak was called “provocation”, since part of the data is not collected and stored by Russian tax authorities, and their structure was different from the adopted in the service. Data can be compilation from stolen bases of government agencies. The owner of the base clearly placed it in open access for negligence - this is a frequent case with large data sets that are stored in the cloud and, for example, forget to shoot.
A leak in Sberbank. On Wednesday, Kommersant discovered an announcement for the sale of data from more than 60 million owners of Sberbank credit cards. The trial fragment of the base of 200 people was genuine. This gave Sberbank the reason to officially recognize the leakage of data from only these 200 people, but it is obvious that this is only the tip of the iceberg - Kommersant correspondents, requesting materials about themselves (the authors of the announcement sell data on 5 rubles per person), received reliable information: they coincided with the number of agreements on the opening of credit cards and the name of the employees who signed them. In Sberbank, it is assumed that a source of leakage was an employee with a high level of administrator rights. The stolen data can be used for phishing or other types of fraud using social engineering.
Application surveillance. Data leaks from banks and state bodies are only one way to lose them. On Tuesday, The Bell analyzed how the TOP-100 of Russian applications for Android treats users. The results were predictable. The most popular services transmit data to dozens of third parties (often through an unprotected http protocol), install dozens of advertising trackers and try to get a maximum of access to the functions of the device - for example, record audio without notifying the user.
What does it mean?
The growing number of leaks from state bodies and the largest and most protected companies confirms the simple consideration that one of the creators of modern cryptography Bruce Schneier ( here ) and the journalist in the field of cybersecurity Brian Krebs ( here ) wrote. Whoever you are, most likely, your personal data are already stolen and are in the hands of attackers. This means that your main goal should not be the protection of the data itself, but the prevention and minimization of damage from their use.
What to do?
The main thing is not to trust anyone. But there are three more important rules, following which it will prevent attackers from using your data for the theft of money or secrets.
Wherever possible, use a two -stage authentication in order to confirm potentially dangerous actions. It should be remembered that authentication using SMS is unreliable - it is completely easy to intercept cell traffic. Here is a relatively fresh instruction on how to configure a reliable two -stage authentication from The New York Times.
Make sure that your passwords to different services differ and are well protected. A relatively safe way to organize such a system is a password manager. The recent rating of the best managers for various devices and browsers from Wired is here . The main thing is to come up with a reliable password for the manager himself. Here are our favorite instructions for inventing passwords from Bill Barra, who came up with the rule of the mandatory figure, the capital letter and special systems, and then was disappointed in it.
Make sure that the channels of authenticity are belonging to you. For example, if you bought a SIM card from your hands, its legal owner can intercept your SMS-including verification.